Subject: Re: NetBSD 1.5.2 default configuration
To: None <xs@kittenz.org>
From: Wojciech Bojdol <wojboj@htcon.pl>
List: tech-security
Date: 02/03/2002 16:36:33
On Sun, Feb 03, 2002 at 03:10:06PM +0000, xs@kittenz.org wrote:
> It's more open and "friendly".

In my opinion it's too insecure.
But - for people like me is good small script that will change the default
for my needs.

> It depends on the medium I store them on.

It's between 0.01$ and 1$ ? :)

> How much does it cost to type
> gzip -d wtmp.xx.gz; last -f wtmp.xx ? :)

It cost me time. On old machines - could be to much of time.
last with support of pipe could be good, but now the best is to not compress
that files.

> > If you want to give users right to change their crontabs via www
> > you have to do some script suid root.
> 
> Not really, put the output from crontab -l into a textarea, and then when
> the user clicks "save" pipe the current contents of that textarea into
> crontab -. Assuming whatever user executes the (nonsuid) script has
> rights to run crontab, which it would if you used a system like apache's
> suEXEC.

In my oppinion it's insecure model.
Good, tested suid script/program would be better for that.

> Or as a users login shell.

That users need to run pppd as root ?

-- 
Wojciech Bojdoł
High-Tech Consulting